ShinyHunters
Also known as: bling libra, unc6240
Profile
ShinyHunters (also tracked as UNC6240) is a data-theft and extortion group whose current activity has been documented since 2025 and which, according to the FBI, has breached more than 140 organisations and collected at least $70 million in payments. Its core method is large-scale data theft: it abuses corporate SSO accounts, third-party suppliers and cloud SaaS platforms (Salesforce, Snowflake), and since 2026 has been mass-exploiting a zero-day in Oracle PeopleSoft (CVE-2026-35273), bypassing WAFs through URL encoding to drop web shells. Victims span education, technology, healthcare, agriculture, transport and logistics, finance, telecoms and government, with notable cases including the theft of 2-3 TB of data from the FBI's job application portal (FBIJobs.gov), which was also defaced, and a breach at Dutch telecoms operator Odido. A distinguishing trait is its strong public messaging: it denies that its activity amounts to extortion and framed the FBI incident as a 'marketing campaign'. Despite the September 2026 arrest in the Netherlands of an alleged 24-year-old leader, the group remains active and denied any link to that individual.
Active since: 2025
Initial access
- Exploitation of the Oracle PeopleSoft zero-day CVE-2026-35273
- WAF rule evasion via URL encoding
- Compromise of corporate SSO accounts
- Compromise of third-party suppliers and trusted vendors
- Abuse of cloud SaaS platforms (Salesforce, Snowflake)
Tools
Web shells, MeshCentral remote management agent (MeshAgent), Neo-reGeorg (tunnelling proxy), SIDEEYE, Ple64.exe
What defenders should watch
- Prioritise patching Oracle PeopleSoft against CVE-2026-35273 and review internet-facing systems for web shells or anomalous uploaded files predating the patch.
- Confirm that your WAF normalises and decodes URLs before applying rules: the group evades filters with encoding tricks, so perimeter filtering alone is insufficient.
- Monitor for unauthorised remote management agent installs (MeshCentral/MeshAgent) and Neo-reGeorg-style tunnelling traffic, both indicators of persistence and lateral movement.
- Harden corporate SSO with phishing-resistant MFA and review tokens, OAuth integrations and connected-app permissions in SaaS platforms such as Salesforce and Snowflake.
- Inventory and audit third-party access: a significant share of intrusions arrives through suppliers rather than your own perimeter.
- The September 2026 arrest of an alleged member has not stopped the group's activity; sustained monitoring is advisable.
Most affected countries
- United States21
- Germany1
- France1
- United Kingdom1
- Israel1
- Sweden1
Most affected sectors
- Technology11
- Other10
- Pharma & chemicals7
- Healthcare3
- Finance & insurance2
- Professional services2
- Media & entertainment1
- Manufacturing1
Vulnerabilities attributed
| CVE | Severity | EPSS | Active exploitation |
|---|---|---|---|
| CVE-2026-35273 | Critical (9.8) | 9.4% | ⚠ Active exploitation |
Priority mitigations
MITRE ATT&CK mitigations that cover the most techniques used by this group.
- User Account Management (13 techniques covered)
- User Training (12 techniques covered)
- Multi-factor Authentication (8 techniques covered)
- Audit (8 techniques covered)
- Privileged Account Management (7 techniques covered)
- Password Policies (6 techniques covered)
- Account Use Policies (5 techniques covered)
- Filter Network Traffic (5 techniques covered)
MITRE ATT&CK techniques
Recent victims
| Organisation | Country | Sector | Claimed | Status |
|---|---|---|---|---|
| 🔒 Comunicado de grupo criminal | — | Other | 9/30/2026 | ◌ Claimed (unverified) |
| 🔒 Entidad desconocida | — | Other | 9/24/2026 | ◌ Claimed (unverified) |
| 🔒 Entidad no identificada | — | Other | 9/23/2026 | ◌ Claimed (unverified) |
| Fresenius Medical Care | Germany | Healthcare | 9/23/2026 | ◌ Claimed (unverified) |
| 🔒 Entidad no identificada | — | Other | 9/22/2026 | ◌ Claimed (unverified) |
| 🔒 Organización sin identificar | — | Other | 9/20/2026 | ◌ Claimed (unverified) |
| 🔒 Organización | — | Other | 9/17/2026 | ◌ Claimed (unverified) |
| Kimberly-Clark | United States | Manufacturing | 9/13/2026 | ◌ Claimed (unverified) |
| State of Florida DMV | United States | Government | 9/7/2026 | ◌ Claimed (unverified) |
| Medela | — | Healthcare | 9/7/2026 | ◌ Claimed (unverified) |
| 🔒 Servicio de datos | — | Other | 9/4/2026 | ◌ Claimed (unverified) |
| NeoGen Corporation | United States | Technology | 9/3/2026 | ◌ Claimed (unverified) |
| Neogen Corporation | United States | Other | 8/29/2026 | ◌ Claimed (unverified) |
| McKesson Corporation | United States | Pharma & chemicals | 8/29/2026 | ◌ Claimed (unverified) |
| Elekta AB | Sweden | Technology | 8/28/2026 | ◌ Claimed (unverified) |
| Jack Henry & Associates | United States | Finance & insurance | 8/28/2026 | ◌ Claimed (unverified) |
| CyrusOne | United States | Technology | 8/23/2026 | ◌ Claimed (unverified) |
| ReliaQuest, LLC | United States | Technology | 8/23/2026 | ◌ Claimed (unverified) |
| NovoCure Limited | United Kingdom | Pharma & chemicals | 8/22/2026 | ◌ Claimed (unverified) |
| BOK Financial | United States | Finance & insurance | 8/22/2026 | ◌ Claimed (unverified) |
| 🔒 Entidad no identificada | — | Other | 8/20/2026 | ◌ Claimed (unverified) |
| Logitech / Streamlabs | — | Technology | 8/18/2026 | ◌ Claimed (unverified) |
| Brinks Home | United States | Technology | 8/18/2026 | ◌ Claimed (unverified) |
| Alcon, Inc. | United States | Pharma & chemicals | 8/18/2026 | ◌ Claimed (unverified) |
| Lumenis Ltd. | Israel | Pharma & chemicals | 8/18/2026 | ◌ Claimed (unverified) |
Sources analysed
- ShinyHunters Defiant After FBI Calls on Members to Come Forward (SecurityWeek, 9/30/2026)
- FBI tells ShinyHunters members to turn themselves in after recent arrest (BleepingComputer, 9/29/2026)
- Dutch Police Arrest 24-Year-Old Amsterdam Man in ShinyHunters Investigation (The Hacker News, 9/29/2026)
- 28th September – Threat Intelligence Report (Check Point Research, 9/28/2026)
- Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells (The Hacker News, 9/26/2026)
Claims are published by the criminal groups themselves and are unverified until the organisation or the press confirms them. Names of natural persons (sole traders, individual professionals) are anonymised under the GDPR. We never link to leak sites or stolen data. To request the removal or anonymisation of an entry, contact the site administrator.
Sources: RansomLook (CC BY 4.0), MITRE ATT&CK®, MISP Galaxy, GDELT.